Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-31813mod_proxy X-Forwarded-For dropped by hop-by-hop mechanismEPSS 3.1%CVE-2022-23942Apache Doris hardcoded cryptography initializationEPSS 3.1%CVE-2020-17528Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent lengthEPSS 3.1%CVE-2017-3157By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a fEPSS 3.1%CVE-2016-6800The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are relEPSS 3.1%CVE-2018-1299In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers usEPSS 3.1%CVE-2018-8023Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions EPSS 3.1%CVE-2021-31812A carefully crafted PDF file can trigger an infinite loop while loading the fileEPSS 3.1%CVE-2021-41561Apache Parquet-MR potential DoS in case of malicious Parquet fileEPSS 3.1%CVE-2023-50292HIGHApache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated usersEPSS 3.0%CVE-2024-56512LOWApache NiFi: Missing Complete Authorization for Parameter and Service ReferencesEPSS 3.0%CVE-2021-26296Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFacesEPSS 3.0%CVE-2016-6804The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operatiEPSS 3.0%CVE-2023-45802Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RSTEPSS 3.0%CVE-2017-12620When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only aEPSS 3.0%CVE-2014-0043In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of partiEPSS 3.0%CVE-2022-44621CRITICALApache Kylin: Command injection by Diagnosis ControllerEPSS 3.0%CVE-2017-12610In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protEPSS 3.0%CVE-2021-27807A carefully crafted PDF file can trigger an infinite loop while loading the fileEPSS 3.0%CVE-2023-31122Apache HTTP Server: mod_macro buffer over-readEPSS 3.0%